Hang on. The first step of this exploit is that "The attacker logs into the victims account on a 2FA enabled web application". How does the attacker do this if the account has 2FA enabled in the first place? And if the attacker can already log into the victim's site, why are the other steps even necessary?
HN user
monsur
This is absolutely right. We are drowning in an tidal wave of books/articles to read, videos to watch, podcasts to listen to etc. Trying to keep up is a fools' errand we must admit to sooner or later. The best we can do is give in and hope to drink a few sips from this ocean.
Naming aside, I think there is some value in a fluent, cross-language methodology for making HTTP requests. While each library adheres to the conventions of its specific language, the overall pattern for making requests looks the same across languages. If you are someone working with APIs in different languages, there is value in having this consistency.
I'm curious to see whether technologies like BitTorrent Sync (and similar products like Space Monkey) gain traction. One cannot deny the importance of backups, especially as we begin storing decades of our lives (photos, videos, etc) online. On the one hand BitTorrent Sync offers a beautiful vision of purely decentralized backups. On the other hand, it requires a critical mass of users to survive (and the number of users must grow as the amount of data in the system grows).
I prefer jwz's "How will this software get my users laid?" http://www.jwz.org/doc/groupware.html
This is precisely why I like Fever as an RSS reader. Fever lets you separate feeds into low-volume kindling and high-volume sparks. Kindling are the feeds you want to keep up with regularly, while items that are mentioned across Sparks bubble up to the top (Its like having your own personal Hacker News).
It is refreshing to read the perspective of how a non-techie views Google and tech. It's a viewpoint that's important to remember.
I have to agree. There is no evidence of what particular attack vectors lead to this exploit. His conclusion are unsubstantiated blanket suggestions.
Nice article, but what's going on with the screenshots on that page? They are greater than 1MB, 02-fonts.png is +5MB and still loading.
Verizon is not the only one who does this. I've seen the same from AT&T and Chase. I'm sure the list of companies that do this is very long.
I want to shout it from the rooftops: Dear Internet, stop telling me to make stuff! Stop telling me to do things!
This whole "cog in the machine" notion is a myth. The world is fascinating, people are fascinating. Always has been, always will be.
I would counter this entire article with one of my favorite quotes, from the movie Adaptation:
"Nothing happens in the world? Are you out of your fucking mind? People are murdered every day. There's genocide, war, corruption. Every fucking day, somewhere in the world, somebody sacrifices his life to save someone else. Every fucking day, someone, somewhere takes a conscious decision to destroy someone else. People find love, people lose it. For Christ's sake, a child watches her mother beaten to death on the steps of a church. Someone goes hungry. Somebody else betrays his best friend for a woman. If you can't find that stuff in life, then you, my friend, don't know crap about life!"
This is really a shame because these companies are making a shitload of money.
And its an Archers of Loaf song, nice!
What about consuming Hollywood movies through legal, online means such as Amazon.com video? You'd still get to watch the movies while giving a vote to legal online streaming.